A5_-_Attachment_WRBR_PCI_Data_Protection_Addendum.pdf

PDF 455 KB Posted

Attached to
WRBR AUTOMATED FEE MACHINES Federal contract opportunity
Solicitation number
140P5325Q0046
Issued by
Department of the Interior National Park Service Southeast Region

About this file

This is a PCI Data Protection Addendum required for contractors working with Wright Brothers National Memorial on automated fee machines that will handle credit card transactions. The contractor must sign this addendum acknowledging their responsibility to protect cardholder data in accordance with Payment Card Industry Data Security Standard (PCI DSS) requirements.

The contractor must maintain an annual information security program and provide Wright Brothers National Memorial with their annual Report on Compliance (ROC) with PCI DSS and their PA-DSS Implementation Guide upon award and any updates. In case of data breach or suspected compromise, the contractor must provide notice within 48 hours and grant access for investigations by the Memorial's staff, contractors, and law enforcement within 48 hours of written request. The contractor must also provide access for auditing cardholder data protection controls upon written request and return or confirm destruction of cardholder data upon contract termination while continuing to protect any remaining data as required by law and PCI DSS standards.

View the file

Other files for this federal contract opportunity

Other files attached to WRBR AUTOMATED FEE MACHINES, newest first.
File Type Posted
Sol_140P5325Q0046.pdf PDF
A3_-_Attachment_WRBR_AFM_Section_508_GPAT_Accessibility.pdf PDF
A4_-_Attachment_IT_and_Security_Requirements.pdf PDF
A2_-_Price_Schedule.xlsx XLSX spreadsheet
A1_-_WRBR_AFM_Scope_of_Work_-_Final_-_Revised_7-16-205.pdf PDF
A6_-_DOL_Wage_Determination.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PCI Data Protection Addendum Requirement

The contractor must sign the following PCI Data Protection Addendum:

Whereas, National Park Service, Wright Brothers National Memorial, is a merchant that conducts transactions that include credit card payments and <contractor> is a service provider that is provided cardholder data or access to cardholder data, both parties must protect cardholder data in accordance to the Payment Card Industry Data Security Standard (PCI DSS).

<Contractor> acknowledges that when it is provided cardholder data or access to cardholder data, it shall protect that data in accordance with requirements specified in the PCI DSS.

<contractor> is responsible to provide protection for all cardholder data that it collects, processes, stored or transmits.

<contractor> shall comply with the following requirements:

• Maintain an information security program to protect cardholder data and validate compliance to the PCI DSS on an annual basis.

• Provide a copy of <contractor> Report on Compliance (ROC) with PCI DSS to Wright Brothers National Memorial on an annual basis.

• Provide a copy of the <contractor> PA-DSS Implementation Guide to Wright Brothers National Memorial upon award and upon any updates to the guide.

• If Wright Brothers National Memorial cardholder data is compromised or suspected to have been compromised while in the possession of <contractor>, provide notice to the client of actual or potential data breach within forty-eight (48) hours.

• Wright Brothers National Memorial is entitled to conduct its own investigation of any data breaches upon written request to <contractor>. Within forty-eight (48) hours of receiving Wright Brothers National Memorial’s written request for investigation, <contractor> shall provide access to its systems and staff and will support both Wright Brothers National Memorial client staff and contractors as well as law enforcement to conduct the investigation.

• Upon written request of Wright Brothers National Memorial, <contractor> shall provide access to the Wright Brothers National Memorial audit cardholder data protection controls.

• In the event that the contract expiration or termination, <contractor> shall return the cardholder data or provide confirmation of cardholder data destruction to Wright Brothers National Memorial. <contractor> shall continue protecting cardholder data to the extent required by law and by the PCI DSS after contract termination.

WRBR AUTOMATED FEE MACHINES

Appendix: PCI Data Protection Addendum

Wright Brothers National Memorial

Contractor Name: ______________________________________

Contract Number: ______________________________________

Name, Title of Contractor PCI DSS Compliance representative:

Signature and Date: ________________________________

PCI Data Protection Addendum Requirement

File details come from the government source that posted it. Updated .